• [^] # Re: Pas Matrix donc

    Posté par . En réponse au journal Matrix.org piraté. Évalué à 4.

    D'après leur blog:

    We were using Jenkins for continuous integration (automatically testing our software). The version of Jenkins we were using had a vulnerability (CVE-2019-1003000, CVE-2019-1003001, CVE-2019-1003002) which allowed an attacker to hijack credentials (forwarded ssh keys), giving access to our production infrastructure. Thanks to @jaikeysarraf for drawing this to our attention.